The post provides a walkthrough of the THM Sticker Shop challenge, which involves exploiting a Blind XSS vulnerability to obtain a flag. The feedback form in the web application is vulnerable, allowing the attacker to inject malicious JavaScript that retrieves and exfiltrates sensitive data to an external server. The post details the reconnaissance process, exploitation techniques, and the payload used to capture the flag, highlighting the importance of secure coding practices and practical web security measures.

3m read timeFrom infosecwriteups.com
Post cover image
Table of contents
THM Sticker Shop WalkthroughChallenge DescriptionReconnaissance

Sort: